Kinsing targeting cloud servers (Campaign)
ID: fab147a4-efda-52fb-bbb0-27e1757cafa6
STIX ID: report--fab147a4-efda-52fb-bbb0-27e1757cafa6
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-05-16
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers observed Kinsing malware campaigns targeting Linux cloud infrastructure and Apache Tomcat servers; the attackers exploit vulnerabilities to install backdoors and the XMRig Monero miner and hide malicious files in unconventional filesystem locations (e.g., /var/cache/man/cs/cat1/, /var/lib/gssproxy/rcache/) to evade detection. Activity has been ongoing since mid-2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
